Privacy
There is no account to create on BuildBatch, and nothing to sign up for. What you type never leaves your device: BuildBatch sets no cookie, and a project you save is kept in this browser and nowhere else. Visits to the pages are counted, without a cookie, as counting visits explains. This page says exactly what is kept, where, and how to delete it.
What you type, and what is kept
Using a calculator stores nothing
A calculator, the room planner and the room refresh planner are programs that run inside your browser. When you enter a room size, the arithmetic happens on your own device and the answer is drawn on the page. Nothing you type is sent to us or to anyone else: no request carries a measurement, a name, a price you entered or a decision you made.
Some pages do ask this site one question of their own. The paint and flooring calculators ask whether a published product fits an estimate. The room refresh planner, wherever it appears (it is also on the wallpaper, tile and skirting board calculator pages), asks which products the catalogue has published for a material, when you choose a catalogue product for paint or flooring. That request names the calculator or the material, nothing else, and the answer is public information. If it fails, the planner and the calculators carry on without it.
Some links carry a room from one tool to another so that you do not type it again: from the room planner or a calculator into a room refresh. They put the measurements after a “#” in the page address. Browsers do not send that part of an address to the server, so the measurements stay on your device. The visit counter leaves that part out too: see counting visits.
- Nothing is kept. Close the tab or reload the page and everything you entered is gone, unless you deliberately saved it to a project.
- Visits are counted. The pages load a visit counter run by Cloudflare, described under counting visits. There are no tracking pixels and no A/B testing. Cloudflare, which hosts the site, shows BuildBatch totals of the requests it serves, and a sample of single requests for its security, as what the web host can see explains. We cannot see how many rooms you calculated or what you entered.
- One thing is loaded from somewhere else: the visit counter's script, from Cloudflare. The typefaces are served from this site, not from a font service. There are no embedded videos, maps, social buttons or adverts.
- No account, and nothing to sign up for. Nothing on these pages asks for a name, an email address or a phone number.
- No cookies at all on the public pages: the calculators, the planners, the guides and these information pages set none. Cloudflare says its visit counter stores nothing in your browser. There is no cookie banner. To stop the counter, see counting visits. (The private admin, used only by staff who sign in, sets a sign-in cookie for them. The host, Cloudflare, can set cookies in one case, when it stops a browser to check it: see the host.)
Copy and print. “Copy list”, “Copy buying list” and “Copy merchant enquiry” put text on your device's clipboard, and “Print” hands the page to your own browser and printer. All of them stay on your device; the merchant enquiry is text for you to paste wherever you choose, and BuildBatch does not send it. Your browser and operating system have their own rules about the clipboard and about printing; those are theirs, not ours.
Saving a project stores it in this browser
A project lets you keep several estimates together — the paint for two bedrooms and the flooring for a hall — and see one shopping list for all of them. To do that it has to remember them, so a project is saved on this device, using your browser's local storage. It is not sent anywhere and it is not synchronised to any other device. Open the site on your phone and your projects are not there, because they never left the computer you made them on.
What is saved: the name you gave the project, the name you gave each area or room, the measurements and product figures you typed, and, for a room refresh batch, which lines you marked as needed, already owned or not needed. That is all. The answers are not saved — they are worked out again from your measurements every time you open the project, so a project can never disagree with a corrected calculator.
It is stored under the name buildbatch.projects.v1. You can see it in your browser's developer tools, under local storage.
To remove it: the projects page has a “Delete everything saved on this device” button, which removes all of it at once. Deleting a single project removes that one. Clearing this site's data in your browser settings does the same thing. Nothing we do can stop you: it is on your machine, not ours.
To keep it, or move it: the projects page can export everything to a file, and read that file back. The file is plain readable JSON, and it is yours — put it in your own backups, send it to yourself, or move it to another computer.
If your browser is set to block storage, or you are in a private window, the projects page still works for as long as the tab is open and tells you that nothing is being saved.
What the web host can see
This is the part that is easy to overstate, so to be exact: the calculator sends nothing, but asking for a web page is itself a request, and the computer serving it can see that request. That is true of every website.
The host can see things like the address of the page you asked for, the time, your IP address and which browser you used. It cannot see the measurements you typed, because those never form part of a request: links that carry a room between tools keep the measurements after the “#”, which browsers do not send. Opening a saved project puts its identifier in the address: a short code made when the project was created, from the time and a random part, which does not include its name or contents. It means nothing outside your browser.
The host: Cloudflare
BuildBatch runs on Cloudflare Workers, a service of Cloudflare, Inc., so every request to this site reaches Cloudflare's network. This is what Cloudflare's own privacy policy and documentation say about that.
- What it processes. When you use a website that runs on its services, Cloudflare processes your interactions with that site. That may include your IP address, how your traffic was routed, and other information about the traffic to and from the site.
- On whose behalf. Cloudflare handles the logs it makes available to BuildBatch, and what passes through its network, for BuildBatch and on its instructions (as a processor). For the rest of what it collects, Cloudflare decides the use itself (as a controller), under its own privacy policy. Cloudflare also keeps information it works out from traffic to run and protect its network, such as request volumes, error rates and threat scores for IP addresses.
- Where. Cloudflare says it mainly stores information in the United States and the European Economic Area, and that it may transfer and access it from other countries. What Cloudflare handles for BuildBatch in the United States goes there under the UK's adequacy regulations for the United States, through the UK Extension to the EU-US Data Privacy Framework, in which Cloudflare takes part; otherwise under the UK's International Data Transfer Addendum in Cloudflare's data processing terms.
- For how long. Cloudflare's privacy policy gives no fixed period. It keeps personal information for as long as its business purposes or the law need, then deletes it. Its data processing terms keep the personal data it handles for BuildBatch, which includes those logs, until BuildBatch's agreement with Cloudflare ends, or sooner once it is no longer needed.
- The site's own request log. Cloudflare can keep a log of each request that the site's own program on Cloudflare (its Worker) handles: the request and the response, with details Cloudflare adds, such as the country the request came from. If that log is switched on, Cloudflare keeps it for 3 days on its free plan and for 7 days on its paid plan. For BuildBatch it is switched off, and BuildBatch is on Cloudflare's free Workers plan: both were checked in Cloudflare's dashboard on 29 September 2026. The setting is written into the site's own configuration, so a new release cannot switch the log on unnoticed.
- The totals BuildBatch sees. Cloudflare measures every request it receives, with no script on the pages, and shows BuildBatch the totals. For the site's Worker, that is how many requests there were and how many failed, for up to three months back. Because the site is on its own domain, Cloudflare also shows the number of requests, the amount of data sent, the number of unique visitors and the requests from each country. It counts visitors by their IP addresses, and the totals include bots and crawlers, not just people. Cloudflare's security dashboard also shows BuildBatch a sample of single requests from the last 7 days (the time, the IP address, the page, the country and the browser), and a sample of the requests its protections acted on from the last 24 hours. BuildBatch looks at them only to keep the site working and safe.
- Reports of failed requests. Every page tells your browser that, if a request to this site fails because of a network problem, it may report the failure to Cloudflare (Network Error Logging). The report goes to Cloudflare, not to BuildBatch. Cloudflare says it works out the network, the country and the area the report came from, keeps your IP address only in memory while it receives the report, and does not log it.
- Why, and on what basis. To serve the pages and to keep the site working and safe. Lawful basis: legitimate interests (UK GDPR Article 6(1)(f)): a page cannot be served without the request for it, and a site has to be protected from attacks.
The database: Supabase
The product catalogue and the staff admin keep their records in a database run for BuildBatch by Supabase, in London (the region Supabase calls eu-west-2), chosen when the project was created on 28 September 2026 and fixed from then on. The site cannot be built without it. Your browser never talks to Supabase: when a page asks which products are published, this site's own server asks the database, and the question names only the calculator or the material.
Counting visits
To learn which pages are useful, BuildBatch counts visits with Cloudflare Web Analytics, a service run by Cloudflare, which also hosts the site. A small script of BuildBatch's own, served from this site, loads Cloudflare's counter script, from static.cloudflareinsights.com, unless you have asked it not to, as to stop it explains. Cloudflare's script sends its reports to cloudflareinsights.com. The private admin and the page shown for an address that does not exist do not load it. This is what Cloudflare's own documentation says about it, and how to stop it.
- What it sends. Timings from your browser: how long the page took to load and to appear, and how quickly it responded when you used it, with how much memory it used. With them go the page's address, the address of the page that linked to it, a random code made in your browser for that one page view, and the names and versions of your browser and operating system. For the slowest moments, it names the part of the page involved, such as a button, by its name in the page's code.
- Not what you type. It measures how the page behaves, not what is in it or what you enter. Cloudflare says Web Analytics does not log the part of an address after “?”. We also read the counter's script as Cloudflare published it on 2 September 2026: it removes the part after “?” and the part after “#” from both addresses before sending them, so the measurements that links carry between the tools are not sent. Cloudflare can change the script at any time, so this is checked again whenever this page is reviewed.
- No cookie, and nothing kept in your browser. Cloudflare says the script stores nothing in your browser and reads no cookie or other stored data. So the counter adds no cookie. BuildBatch's own script, which loads it, looks for one thing in this browser's storage: whether you have asked for your visits not to be counted, described next.
- Your IP address. As with any request, each report reaches Cloudflare from your IP address. Cloudflare says the counter drops the address at the nearest Cloudflare data centre and does not keep it in its main databases or logs. Cloudflare also says the reports may be handled in a different country from the one they came from.
- What BuildBatch sees. Totals, not people: page views and visits for each page, the websites that sent people here, and totals by country, browser, operating system and kind of device, with how quickly the pages loaded. Cloudflare says it does not track individual people across the websites that use it. BuildBatch also sees the totals Cloudflare shows it as the host, described under what the web host can see.
- Why, and on what basis. To learn which pages are useful, so that the site can be made better. Lawful basis: legitimate interests (UK GDPR Article 6(1)(f)). You can object at any time, as the next items say.
- For how long. Cloudflare keeps every report in full for 7 days, then keeps about a tenth of them. BuildBatch can look back six months. Cloudflare's documentation does not say when that tenth is deleted.
- To stop it. Use the button under this list, “Stop counting my visits on this browser”. It is free and it works on this site itself: from the next page you open, BuildBatch's own script no longer loads the counter in this browser, so the counter sends nothing from it. “Count my visits again” undoes it. The choice is kept in this browser's local storage under the name
buildbatch.visit-counter.v1, not in a cookie, and it applies to this browser only: on another browser or device, use the button there too. To know your choice, BuildBatch's script looks for that one name each time a page loads, and reads nothing else there. If your browser sends the Global Privacy Control signal, BuildBatch takes it as the same choice and does not load the counter while the signal is on. A browser that will not let this site look in its storage is not counted either, and nor is one with JavaScript switched off. Cloudflare says ad blockers block the counter's script, including Adblock Plus, Brave and the DuckDuckGo extension. However the counter is stopped, every page and tool works as before.
If you email BuildBatch
The site's one address is contact@buildbatch.co.uk. A message sent to it is passed on by Cloudflare, which runs the site's email address as it runs the site, to Angelos Hallaci's own Outlook.com mailbox, run by Microsoft under Microsoft's privacy statement.
- What BuildBatch keeps. Your email address, your name if your email carries it, and what you wrote. They are used only to deal with what you wrote about and to answer you: you are not added to any list, and your message is not passed to anyone else.
- For how long. Until what you wrote about is dealt with. Then your message and BuildBatch's reply are deleted from the mailbox; Outlook.com can still recover a deleted message for 30 days. Cloudflare also keeps a record of each email it passes on (who sent it, to which address, its subject line and when) for 31 days, which BuildBatch can see in its Cloudflare dashboard.
- Where. Microsoft may keep the mailbox in the United States or elsewhere. For data from the UK it relies on the UK Extension to the EU-US Data Privacy Framework and on standard contractual clauses. Cloudflare's part is as described under the host.
- Why, and on what basis. To deal with what you wrote about and to answer you. Lawful basis: legitimate interests (UK GDPR Article 6(1)(f)): you asked for an answer, and nothing else is done with your message.
If that ever changes
Two changes are possible later, and neither has happened:
- Counting what happens in the room refresh planner. We would like to know whether the room refresh planner is useful. The code has a place for nine named counts (a batch started, a room measured, a batch completed, a list copied, an enquiry copied, a batch printed, a batch saved, a line changed, a reviewed offer opened) and it is switched off: none of the nine is counted or sent. If it is ever switched on, this page will describe it before it starts, and by design it cannot carry a measurement, a name, a price or anything that identifies you.
- Links to merchants. If a link to a shop is ever added, it will be marked where you can see it, and following it takes you to that company's website, under their privacy policy and not ours. There are no such links today.
Neither will be added quietly. The change would appear on this page first.
Your rights, and who is responsible
UK data protection law gives you rights over personal data held about you — to see it, correct it, have it deleted, limit how it is used, object to it being used, and to complain to the Information Commissioner's Office, which becomes the Information Commission on 30 September 2026. Those rights need somebody to address them to.
The person responsible for this site under UK data protection law (the data controller) is Angelos Hallaci, who runs BuildBatch. To ask about your data, to use any of those rights, or to complain about how BuildBatch has handled your data, email contact@buildbatch.co.uk. A complaint is acknowledged within 30 days.
Your right to object. Everything described on this page rests on legitimate interests, so you can object to any of it: email contact@buildbatch.co.uk. For the visit counter there is also the button under counting visits.
The site itself holds nothing about you, and the only records of your visit are Cloudflare's, described under what the web host can see and counting visits.
The ICO's guidance for the public is at ico.org.uk/for-the-public.
How to check any of this
You do not have to take our word for it. Open your browser's developer tools, go to the network tab and reload a calculator page: every request goes to this site, apart from the visit counter's, unless you have stopped it: its script, from static.cloudflareinsights.com, and its reports, to cloudflareinsights.com. The application tab shows no cookies (unless Cloudflare has stopped this browser to check it, as the host's cookies explains), and no stored data until you save a project or stop the visit counter. The site's code is plain, readable JavaScript that you can read in the same tools.